Security Budgets 2027: Making the Case for Human Risk

Budget Season Opens Against a Tougher Backdrop
Late summer is when 2027 security budgets start taking shape, and this planning season begins from a harder starting position than most CISOs have faced in years. Budget growth has slowed to a crawl, headcount is stretched, and finance teams are asking sharper questions about what every line item actually returns. The programs that survive scrutiny will be the ones that arrive with evidence.
The most recent industry benchmark - the August 2025 Security Budget Benchmark from IANS Research and Artico Search, based on input from 587 CISOs - found that average security budget growth slowed to 4% year over year in 2025, the lowest in five years, down from 8% in 2024. Security budgets also shrank as a share of overall IT spend, falling from 11.9% in 2024 to 10.9% in 2025. Headcount growth slowed to 7%, and a striking 89% of CISOs described their staffing as stretched thin or insufficient.
The 2026 edition of that benchmark has not yet been published, so treat these as the latest available reference points rather than this year's figures. But the direction of travel is what matters for planning: the era of security budgets growing automatically is over, and 2027 requests will be judged line by line.
The Market Grows, but Scrutiny Grows Faster
None of this means security spending is collapsing. Gartner forecast worldwide end-user spending on information security at 213 billion dollars in 2025, rising toward roughly 240 billion dollars in 2026. The market keeps expanding - but within each organization, that spend is being reallocated and interrogated rather than simply increased.
For a CISO, the combination of a growing market and a flat internal budget means one thing: competition between line items. Tools with unclear utilization get consolidated. Programs that cannot show measurable risk reduction get trimmed to fund the ones that can. Awareness and human risk programs have historically been vulnerable in exactly this environment, because too many of them report activity - courses assigned, videos watched - instead of outcomes. That is a fixable weakness, and the data to fix it now exists.
The ROI Evidence for the Human Risk Line Item
The strongest recent ammunition comes from KnowBe4's 2026 benchmarking research, published in July 2026 and covered by Business Wire: across 42 million phishing simulations involving 14.8 million users at 64,000 organizations, sustained security awareness training cut phishing susceptibility by 79% globally within one year.
That is the kind of number a budget defense is built on, for three reasons:
- It is an outcome, not an activity. A 79% reduction in the probability that an employee falls for a phish is a direct reduction in the likelihood of the incident chain that starts with a click - credential theft, business email compromise, ransomware deployment.
- It is benchmarkable against your own data. A phishing simulation program produces your organization's baseline click rate and its trend over time. You are not asking the CFO to trust an industry study; you are showing them your own curve bending down and citing the study as corroboration.
- The unit economics are favorable. Awareness and simulation programs are priced per seat, cost a fraction of most security tooling categories, and address the attack vector that consistently tops root-cause lists. Few line items on the security budget can claim a measured 79% improvement on the risk they target.
Presented this way, the human risk line item stops being the soft, cuttable training budget and becomes one of the most defensible entries on the sheet.
The SMB and MSP Angle
The squeeze is even tighter downmarket. ESET's June 2026 SMB cyber readiness research, published on WeLiveSecurity, found that budget constraints are the number one barrier SMBs cite to improving their security. For MSPs, that is not a reason to avoid the conversation - it is the shape of the offering: SMB clients need maximum measurable risk reduction per euro or dollar, which is exactly the profile of a managed awareness and simulation program.
An MSP that walks into a renewal with the client's own click-rate trend, completion data and a benchmark comparison is selling documented risk reduction at SMB-friendly pricing. In a budget-constrained market, that beats every pitch built on fear.
How to Present the Line Item This Season
- Baseline before you ask. Run a phishing simulation now so your 2027 request opens with your organization's real susceptibility number, not a generic threat slide.
- Show the curve, cite the benchmark. Pair your internal trend with the published 79% one-year reduction to show the trajectory sustained training delivers.
- Anchor to obligations. Cyber insurance questionnaires and compliance frameworks increasingly require awareness training and simulated phishing - position the line item as satisfying documented requirements, not discretionary spend.
- Highlight the labor math. With 89% of CISOs reporting stretched staffing, automation matters. A platform like empowsec that automates enrollment, campaign scheduling and reporting lets a small team run a continuous program without adding headcount - which is itself a budget argument.
- Report outcomes quarterly. Make click rate, report rate and time-to-report standing metrics in your security reporting, so next year's budget defense is already written.
Key Takeaways
- Budget growth is at a five-year low - 4% in the latest IANS/Artico benchmark, with security's share of IT spend falling to 10.9% - so every 2027 line item needs evidence behind it.
- The market still grows toward roughly 240 billion dollars in 2026 per Gartner, but inside organizations that means reallocation and scrutiny, not automatic increases.
- Human risk has the receipts: sustained awareness training cut phishing susceptibility 79% in one year across 42 million simulations - an outcome metric most security categories cannot match.
- For SMBs and MSPs, budget constraints are the top barrier, which favors per-seat programs with measurable results over big-ticket tooling.
- Baseline now, report quarterly, anchor to insurance and compliance - and let your own falling click rate make the budget case for you.


